>Previously, when the originator of Stuxnet was assumed by many to be

The Times blithely repeats the "myrtus" story (which links the malware
tangentially to the Book of Esther) rather than seeing it as "my RTU s"
(where RTUs are components of a SCADA system).

Also it is perhaps noteworthy that the stories today are almost entirely
concentrating on the payload (the code that messed with the industrial
control systems) rather than the distribution system -- which could have
come from an entirely different source (either written to order, or
indeed provided as COTS!)

>The certificates stolen from Realtek and JMicron used to sign
>rootkits have been linked together by the presence of both companies
>at Hsinchu Science Park in Taiwan.  Presumably inferring that either
>physical security head been breeched or that some sort of
>bribery/infiltration had taken place in those buildings.  

The off-the-record (sorry) information I have is that there wasn't all
that much physical security to breach, along with a very wide choice
indeed as to who to bribe.  viz: these certificates were apparently not
being treated with the respect they deserved :(

